Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.
Link | Tags |
---|---|
http://marc.info/?l=vuln-dev&m=102221487407632&w=2 | mailing list |
http://www.securityfocus.com/bid/4823 | vdb entry exploit |
http://www.iss.net/security_center/static/9160.php | vdb entry |